|
292891
|
- |
|
sap
|
netweaver
|
Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the MessagingSystem Performance Data via unspecified vector…
|
NVD-CWE-noinfo
|
CVE-2012-1292
|
2024-11-21 10:36 |
2012-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292892
|
- |
|
sap
|
netweaver
|
Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecifie…
|
NVD-CWE-noinfo
|
CVE-2012-1291
|
2024-11-21 10:36 |
2012-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292893
|
- |
|
sap
|
netweaver
|
Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1290
|
2024-11-21 10:36 |
2012-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292894
|
- |
|
sap
|
netweaver
|
Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or …
|
CWE-22
Path Traversal
|
CVE-2012-1289
|
2024-11-21 10:36 |
2012-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292895
|
- |
|
utc
|
utc_fire_\&_security_ge-mc100-ntp\/gps-zb_master_clock_device
|
The UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock device uses hardcoded credentials for an administrative account, which makes it easier for remote attackers to obtain access via an HTTP sessi…
|
CWE-255
Credentials Management
|
CVE-2012-1288
|
2024-11-21 10:36 |
2012-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292896
|
- |
|
easyvista
|
easyvista
|
The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name i…
|
CWE-287
Improper Authentication
|
CVE-2012-1256
|
2024-11-21 10:36 |
2012-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292897
|
- |
|
advantech
|
advantech_webaccess
|
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: t…
|
CWE-352
Origin Validation Error
|
CVE-2012-1235
|
2024-11-21 10:36 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292898
|
- |
|
advantech
|
advantech_webaccess
|
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an…
|
CWE-89
SQL Injection
|
CVE-2012-1234
|
2024-11-21 10:36 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292899
|
- |
|
pluck-cms
|
pluck
|
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in pluck 4.7 allow remote attackers to hijack the authentication of admins for requests that (1) modify the admin email address…
|
CWE-352
Origin Validation Error
|
CVE-2012-1227
|
2024-11-21 10:36 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292900
|
- |
|
dolibarr
|
dolibarr_erp\/crm
|
Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file paramete…
|
CWE-22
Path Traversal
|
CVE-2012-1226
|
2024-11-21 10:36 |
2012-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|